Sysdream
18 exploits
Active since Apr 2016
ViMbAdmin 3.0.15 - Cross-Site Request Forgery in DomainController and MailboxController
CVSS 8.8
SPIP < 3.1.2 - Authenticated Remote Code Execution via Crafted INCLUDE/INCLURE Tag
CVSS 8.8
SPIP < 3.1.2 - Cross-Site Request Forgery via XML Validator
CVSS 8.8
SPIP < 3.1.2 - Path Traversal via var_url Parameter
CVSS 7.5
PhpCollab < 2.5.1 - Authenticated Arbitrary File Upload via Client Logo Upload
CVSS 8.8
phpcollab < 2.5.1 - Unauthenticated SQL Injection via project or id Parameters
CVSS 9.8
EyesOfNetwork < 5.0 - Authenticated SQL Injection via bp_name, display, search, equipment, or type Parameter
CVSS 7.2
EyesOfNetwork eonweb < 5.0-0 - Authenticated OS Command Injection via selected_events[] Parameter
CVSS 8.8
Dolibarr < 7.0.2 - SQL Injection via Integer Parameter
CVSS 9.8
Centreon 2.5.3 - Remote Command Execution
Zimbra Collaboration Server < 8.5 - Cross-Site Request Forgery via SOAP BatchRequest
CVSS 8.8
Proxmox VE 3/4 - Insecure Hostname Checking Remote Command Execution
UCOPIA Wireless Appliance < 5.1.7 - OS Command Injection via chroothole_client Argument
CVSS 8.2
UCOPIA Wireless Appliance < 5.1.8 - Authenticated Privilege Escalation via Less Command Shell Metacharacter Injection
CVSS 7.2
gespage < 7.4.9 - SQL Injection via show_prn or show_month Parameter
CVSS 9.8
OpenFire 3.10.2 < 4.0.1 - Multiple Vulnerabilities
Nuxeo Platform 6.0, 7.1-7.3 - Authenticated Path Traversal and Remote Code Execution via X-File-Name Header
CVSS 8.8
AudioCodes IP phone 420HD <2.2.12.126 - RCE
CVSS 8.8